-
Notifications
You must be signed in to change notification settings - Fork 51
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Vulnerabilities in the Auth0.OidcClient.Core assembly #328
Comments
This should be fixed here. Please try our latest version of the SDK. |
Thanks for the prompt response. |
Sorry about that. The fix in Can you try updating (probably explicitly installing) Auth0.OidcClient.Core to 4.0.1 and see if it helps? |
That will work for now. Thanks |
Checklist
Description
We use the Auth0.OidcClient.WinForms NuGet package in our software.
Mend (WhiteSource) open source scans detected some transitive dependencies coming from the Auth0.OidcClient.Core assembly containing known medium vulnerabilities.
The affected packages are the last two in the list below:
Auth0.OidcClient.Core → Microsoft.IdentityModel.Protocols.OpenIdConnect (6.12.2) → System.IdentityModel.Tokens.Jwt (6.12.2) → Microsoft.IdentityModel.JsonWebTokens (6.12.2)
Reproduction
Do Mend (WhiteSource) open source vulnerability scan for binaries that reference Auth0.OidcClient.WinForms.
Additional context
No response
auth0-oidc-client-net version
3.2.8
.NET version
4.8
Platform
Windows
Platform version(s)
10
The text was updated successfully, but these errors were encountered: